CVE-2023-33063: Use After Free in DSP Services
Memory corruption in DSP Services during a remote call from HLOS to DSP.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
If vendor remediation or mitigations are unavailable, discontinue use of the affected products: Adobe After Effects 2025; Adobe Dimension; Adobe Experience Manager; Adobe Illustrator 2024; Adobe InDesign 2025; Adobe Prelude; Adobe Substance 3D Sampler; Adobe Substance 3D Stager; Android; Apache Struts; Atlassian Bitbucket; Atlassian Confluence Server and Data Server; Atlassian Confluence Server/Data Center; Atlassian Jira; Azure Logic Apps; Bamboo; FortiGuard FortiPAM; FortiOS; Microsoft Power Platform; Microsoft Windows Operating System; Qualcomm Multiple Chipsets; SAP Business Technology Platform; Trimble ProDesign 3D; VMware Workspace ONE Launcher; WebKit.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is CVE-2023-33063?
CVE-2023-33063 is a use-after-free vulnerability in DSP Services found in multiple Qualcomm chipsets.
How does the use-after-free vulnerability in DSP Services occur?
The use-after-free vulnerability in DSP Services occurs due to memory corruption during a remote call from HLOS to DSP.
Which software is affected by CVE-2023-33063?
Google Android and Qualcomm Multiple Chipsets are affected by CVE-2023-33063.
What is the severity of CVE-2023-33063?
CVE-2023-33063 has a severity value of 7, which is considered high.
How can I fix the use-after-free vulnerability in DSP Services?
To fix the use-after-free vulnerability in DSP Services, apply the patches and updates provided by Google and Qualcomm.